PT-2025-47377 · Gnu+3 · Gnu Grub+3

Published

2025-11-18

·

Updated

2026-05-19

·

CVE-2025-54771

CVSS v3.1

4.9

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GNU GRUB (Grand Unified Bootloader) (affected versions not specified)
Description A use-after-free issue exists in GNU GRUB (Grand Unified Bootloader). The problem stems from an incorrect memory pointer retention during the file-closing process, resulting in an invalid reference to a file system structure. Exploitation of this issue could lead to a Denial of Service, potentially compromising data integrity or confidentiality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

BDU:2025-14788
CVE-2025-54771
OESA-2025-2735
OESA-2025-2736
OESA-2025-2737
OESA-2025-2738
OESA-2025-2739
OPENSUSE-SU-2025:15749-1
OPENSUSE-SU-2025:20163-1
SUSE-SU-2025:21062-1
SUSE-SU-2025:21212-1
SUSE-SU-2025:21223-1
SUSE-SU-2025:4143-1
SUSE-SU-2025:4152-1
SUSE-SU-2025:4196-1
SUSE-SU-2025:4197-1
SUSE-SU-2025:4224-1
SUSE-SU-2025:4305-1
SUSE-SU-2025_4197-1

Affected Products

Debian
Gnu Grub
Red Os
Suse